Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 246

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Michael and Susan Dell to donate $750 million to UT Austin to fund new medical campus
United Airlines slashes 2026 forecast as fuel costs surge
Bike horn for warning oblivious pedestrians
Pet death logistics
Is it okay to leave the toilet seat up in a shared office space?
Movie: My Life as a Dog
Movie: The Blue Caftan
SpaceX says it can buy Cursor later this year for $60 billion or pay $10 billion for 'our work together'
European stocks set to open lower as Trump refuses to lift Strait of Hormuz blockade
Analysis: Warsh emerges from a difficult hearing with his Fed 'regime-change' plan intact